This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Web Mapper Project"

From OWASP
Jump to: navigation, search
(OWASP Web Mapper Project)
 
(2 intermediate revisions by the same user not shown)
Line 13: Line 13:
  
  
What if there are quite a few web applications under your organization, but nobody seems to know all of them (before the talking of application risk assessment)? Then this project may be a right fit for you. This project is designed for the web application asset discovery and tracking automatically.
+
What if there are quite a few web applications under your organization, but nobody seems to know all of them (before the talk of application risk assessment)? Then this project may be a right fit for you.  
 +
 
 +
This project is designed to perform the web application asset discovery and auto tracking with scale.
  
 
==Description==
 
==Description==
Line 44: Line 46:
  
 
* [https://github.com/yangsec888/wmap Latest WMAP source tree.]
 
* [https://github.com/yangsec888/wmap Latest WMAP source tree.]
* [https://github.com/yangsec888/www_wmap WMAP demo web app built under Ruby on Rails 4+]
+
* [https://github.com/yangsec888/www_wmap WMAP web app demo built in Ruby on Rails 5+]
  
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
| valign="top"  style="padding-left:25px;width:200px;" |
 
| valign="top"  style="padding-left:25px;width:200px;" |
 
  
 
== Related Projects ==
 
== Related Projects ==

Latest revision as of 14:28, 15 September 2019

OWASP Project Header.jpg


OWASP Web Mapper Project

What if there are quite a few web applications under your organization, but nobody seems to know all of them (before the talk of application risk assessment)? Then this project may be a right fit for you.

This project is designed to perform the web application asset discovery and auto tracking with scale.

Description

A pure Ruby library for the web application asset discovery and tracking. The tool is useful when you're handling a larger size organization with multiple Internet domains and networks registered under the name. Where both legacy and new web applications are omni-present but nobody seems to be able to provide a complete list of application URLs to you. Yes you can always do it the old way by using tool sets such as NMAP, OWASP Zap web crawler, along with others. But such tool sets could quickly become too much manual-driven and inaccurate, if not impossible. In the contrary, once setup, this project will help you quickly identify all the 'unknown' web application asset, and keep track of them automatically. If you are serious about your organization's Internet web application exposure, this might be the perfect all-in-one footprinting tool you're looking for.

Built as an open source project, the source code is both free and scalable. You're welcome to keep building on top of the current code base, or include it as part of your larger project distribution.

Licensing

The OWASP Web Mapper Project is free to use. In fact it is encouraged!

The OWASP Security Principles are licensed under the Apache 2.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

What is OWASP Web Mapper Project?

The goal is to help you better identify, and keep track of the web application asset under your watch. Ideally we could document various reverse-engineering techniques using by this project and publish it through the OWASP Press. Of course, it will always remain freely available, and any money collected will go directly into the project and to the OWASP Foundation.

Demo

  • Demo A demo web app exploring WMAP library power.


Project Code and Documents

Related Projects

News and Events

  • [January 1 2018] OWASP Web Mapper demo web application released.
  • [August 1 2015] OWASP Web Mapper Project created.


Project Leader


In Print

I'm working on project document. But it's far from become a book at this moment. Instead, please refer to the project hosting site for more project document.

Classifications

New projects.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg